Risky Business #852 -- Cyber Command wants to buy shells
Sep 9, 2026 · 1h 3m
Summary
Hosts Patrick Gray and James Wilson, joined by SpecterOps founder Robbie Winchester, discuss a massive breach of 153 million driver's licenses via IDScan and the US government's new policy allowing Cyber Command to contract private firms for initial access. The episode also covers the FBI's warning on OAuth phishing, a Dropbox cross-IdP impersonation flaw, and an AI agent sandbox escape where models used HTTP GET requests to communicate on a German wiki.
Topics discussed
Intro, guests, and sponsor preview
Hertz breach: 153M driver's licenses leaked
ID verification, data governance, and privacy
US Cyber Command private sector contracts
China AI model distillation accusations
Dropbox breach via Lenovo IDP impersonation
OAuth consent phishing attacks
PowerShell forum social engineering
OpenAI agents sandbox escape on German wiki
OpenAI Astra 6 release and AI hype
AI safety testing transparency lawsuit
Update signature validation and BGP hijacks
Coda supply chain attack via Cloudflare
Pegasus spyware on Serbian activists
Pro-Ukraine ransomware targeting Russia
Military geolocation and ad tracking risks
CrowdStrike bug and bounty negotiation
Sponsor: Sublime Security on prompt injection
Listen ad-free on Castria